You configured wired 802.1X with EAP-TLS on Windows machines. The ISE authentication detail report shows “EAP-TLS failed SSL/TLS handshake because of an unknown CA in the client certificates chain.” What is the most likely cause of this error?

A.

The ISE certificate store is missing a CA certificate.

B.

The Wireless LAN Controller is missing a CA certificate.

C.

The switch is missing a CA certificate.

D.

The Windows Active Directory server is missing a CA certificate.

Correct Answer: A

QUESTION 38

Which two profile attributes can be collected by a Cisco Wireless LAN Controller that supports Device Sensor? (Choose two.)

A.

LLDP agent information

B.

user agent

C.

DHCP options

D.

open ports

E.

CDP agent information

F.

FQDN

Correct Answer: BC

QUESTION 39

Which statement about system time and NTP server configuration with Cisco ISE is true?

A.

The system time and NTP server settings can be configured centrally on the Cisco ISE.

B.

The system time can be configured centrally on the Cisco ISE, but NTP server settings must be configured individually on each ISE node.

C.

NTP server settings can be
configured centrally on the Cisco ISE, but the system time must be configured individually on each ISE node.

D.

The system time and NTP server settings must be configured individually on each ISE node.

Correct Answer: D

QUESTION 40

How many days does Cisco ISE wait before it purges a session from the active session list if no RADIUS Accounting STOP message is received?